A.7.8 Physical
Equipment siting and protection
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (13)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PE-18mostlyaligns with — Both controls focus on physically locating equipment to reduce exposure to unauthorized observation, environmental hazards, and interference.
- PE-19mostlyaligns with — Both address countermeasures against information leakage from electromagnetic emanations and other physical emanation risks.
- PE-14partialaligns with — Both require ongoing monitoring of environmental conditions such as temperature and humidity that affect system operation.
- PE-15partialaligns with — Both seek to protect equipment from water damage and related environmental hazards through siting and protective measures.
- PE-3partialaligns with — Both emphasize physical placement and access restrictions to limit unauthorized entry to areas containing sensitive equipment.
- PE-9partialaligns with — Both require safeguards for power and communications cabling against environmental and interference threats.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-06mostlycovers — By requiring equipment siting and physical separation to prevent unauthorized access, the ISO control satisfies the CSF outcome of managing, monitoring, and enforcing physical access to assets commensurate with risk.
- PR.IR-02mostlycovers — The ISO control's focus on shielding equipment from environmental threats such as fire, water, dust, vibration, and electromagnetic interference directly fulfills the CSF outcome of protecting technology assets from environmental threats.
- DE.CM-02partialaligns with — The ISO guidance to monitor environmental conditions like temperature and humidity aligns with the CSF outcome of monitoring the physical environment to detect potentially adverse events.
- PR.DS-01partialaligns with — Placing sensitive-data equipment to avoid visual eavesdropping and electromagnetic emanation contributes to the CSF outcome of protecting the confidentiality of data-at-rest.
- PR.IR-01partialaligns with — Positioning and physically separating equipment to reduce unauthorized logical or physical access supports the CSF outcome of protecting networks and environments from unauthorized logical access and usage.
Related weaknesses / CWE (11)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263mostlyprevents — Equipment siting helps reduce exposure but is secondary to access-control measures.
- CWE-1278partialmitigates — Proper siting and protection of equipment can reduce exposure to imaging tools.
- CWE-1300partialmitigates — Proper siting and protection of equipment can reduce observable emissions.
- CWE-1319partialmitigates — Equipment siting and protection can reduce exposure to EM sources but does not specifically target fault-injection vectors.
- CWE-1384partialprevents — Requires proper siting and protection of equipment against environmental hazards.
- CWE-200partialprevents — Positioning equipment and shielding emanations reduce the chance that an attacker can observe or capture sensitive data through physical proximity or side-channel leakage.
- CWE-284partialmitigates — Siting equipment to limit unnecessary access and physically separating managed from unmanaged facilities directly restricts unauthorized actors from reaching protected resources.
- CWE-552partialmitigates — Placing equipment away from public or shared areas and segregating organizational facilities lowers the exposure of files, devices, or directories to external parties.
- CWE-732partialmitigates — Physical placement and environmental controls complement permission settings by reducing the opportunity for an attacker who gains physical proximity to exploit overly permissive resource assignments.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005partialmitigates — Physical and environmental protections make it harder for an adversary to gain the close access needed to collect data directly from endpoint storage.
- T1091partialprevents — Restricting physical access and siting of equipment limits the chance of malware being spread via removable media left in or near systems.
- T1200partialprevents — Physical placement and access restrictions reduce the opportunity for an adversary to introduce unauthorized hardware into the environment.
- T1052nonemitigates — Controls that limit physical proximity and environmental access hinder the ability to connect removable media to exfiltrate data.
- T1056nonemitigates — Positioning devices handling sensitive data away from unauthorized viewers reduces the feasibility of shoulder-surfing or other direct observation attacks.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.